wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Ethical Hacking

Total questions: 90

Worksheet time: 46mins

Name
Class
Date
1.

What is ethical hacking?

a)

Unauthorized system access

b)

Authorized system testing

c)

Malware development

d)

Network disruption

2.

Which type of hacking involves gaining unauthorized access to systems?

a)

White Hat

b)

Black Hat

c)

Grey Hat

d)

Red Hat

3.

What is the primary purpose of ethical hacking?

a)

Data theft

b)

System improvement

     

c)

Network disruption

d)

Financial gain

4.

Which hacker type operates with permission to test security?

a)

Black Hat

     

b)

White Hat

c)

Grey Hat

d)

Script Kiddie

5.

What is a disadvantage of ethical hacking?

a)

Improves security

     

b)

Time-consuming

c)

Always illegal

d)

Guarantees no breaches

6.

Which term refers to exploiting software vulnerabilities?

a)

Phishing

     

b)

Brute Force

c)

Bug Bounty

d)

Social Engineering

7.

Which tool is commonly used for network scanning in ethical hacking?

a)

Nmap

     

b)

Photoshop

c)

Excel

d)

Notepad

8.

What is the first phase of ethical hacking?

a)

Reconnaissance

     

b)

Scanning

c)

Exploitation

d)

Maintaining Access

9.

Which component of the CIA triad ensures data is not altered?

a)

Confidentiality

     

b)

Integrity

c)

Availability

d)

Authenticity

10.

Under the Indian IT Act 2000, which section deals with hacking?

a)

Section 43                              

  

b)

Section 66

c)

Section 67

d)

Section 69

11.

What is a key advantage of ethical hacking?

a)

Data loss

     

b)

Security enhancement

c)

System crashes

d)

Legal penalties

12.

Which hacker type operates without malicious intent but without permission?

a)

White Hat

     

b)

Black Hat

c)

Grey Hat

d)

Script Kiddie

13.

What is phishing in ethical hacking terminology?

a)

Network scanning                 

     

b)

Social engineering attack

c)

Password cracking

d)

Vulnerability scanning

14.

Which phase of hacking involves gaining access to the target system?

a)

Reconnaissance

     

b)

Scanning

c)

Exploitation

d)

Covering Tracks

15.

Which skill is essential for ethical hackers?

a)

Graphic design

     

b)

Penetration testing

c)

Web development

d)

Database management

16.

What does the Indian IT Act 2000 primarily regulate?

a)

Physical security                                     

     

b)

Cyber activities

c)

Hardware manufacturing

d)

Software licensing

17.

What ensures data is accessible to authorized users in the CIA triad?

a)

Confidentiality

     

b)

Integrity       

c)

Availability

d)

Authentication

18.

Which type of hacking targets sensitive data for malicious purposes?

a)

Ethical Hacking

     

b)

Black Hat Hacking

c)

Grey Hat Hacking

d)

White Hat Hacking

19.

What is the purpose of the reconnaissance phase in hacking?

a)

Gaining access

     

b)

Information gathering

c)

System exploitation

d)

Hiding evidence

20.

Which amendment to the Indian IT Act introduced stricter penalties for cybercrimes?

a)

2006

     

b)

2008

c)

2010      

d)

2012

21.

Which tool is used for password cracking in ethical hacking?

a)

Metasploit

    

b)

John the Ripper

c)

Wireshark    

d)

Nessus

22.

What is a script kiddie?              

a)

Professional hacker

     

b)

Novice using pre-written scripts

c)

Authorized tester

d)

Government hacker

23.

Which phase of hacking involves hiding evidence of intrusion?

a)

Scanning

     

b)

Exploitation

c)

Maintaining Access

d)

Covering Tracks

24.

Which tool is used for vulnerability assessment in ethical hacking?

a)

Burp Suite                                                               

  

b)

Nmap

c)

Nessus       

d)

Aircrack-ng

25.

What ensures data is only accessible to authorized users in the CIA triad?

a)

Confidentiality                                      

     

b)

Integrity

c)

Availability       

d)

Non-repudiation

26.

Which section of the Indian IT Act 2000 addresses data protection?

a)

Section 43A

     

b)

Section 66

c)

Section 67   

d)

Section 70

27.

What is a key disadvantage of black hat hacking?

a)

Improves security

      

b)

Legal consequences

c)

Enhances skills

d)

Authorized access

28.

Which type of hacker may operate for personal gain without permission?

a)

White Hat

     

b)

Black Hat

c)

Grey Hat

d)

Ethical Hacker

29.

Which tool is used for packet analysis in ethical hacking?

a)

Metasploit

     

b)

Wireshark

c)

Nessus    

d)

John the Ripper

30.

What is the final phase of ethical hacking?

a)

Reconnaissance

      

b)

Exploitation

c)

Covering Tracks

d)

Reporting         

31.

What is reconnaissance in ethical hacking?

a)

Gaining unauthorized access

     

b)

Information gathering      

c)

Exploiting vulnerabilities

d)

Covering tracks

32.

Which type of reconnaissance involves direct interaction with the target?

a)

Passive Reconnaissance

     

b)

Active Reconnaissance

c)

DNS Enumeration

d)

Banner Grabbing

33.

What is passive reconnaissance?                

a)

Scanning network ports

     

b)

Querying public databases

c)

Exploiting systems

d)

Installing malware    

34.

What is footprinting in ethical hacking?

a)

Gaining system access

     

b)

Collecting target information

c)

Hiding evidence

d)

Cracking passwords

35.

Which tool is commonly used for domain name information gathering?

a)

Nmap

     

b)

Whois    

c)

Metasploit

d)

Wireshark

36.

What does a Whois lookup provide?

a)

IP address ranges

     

b)

Domain registration details

c)

Website source code

d)

Network traffic data

37.

How can an ethical hacker find the IP address of a website?

a)

Using ping command

     

b)

Checking browser history

c)

Running a brute force attack

d)

Installing a keylogger              

38.

Which service helps identify the hosting company of a website?

a)

DNSenum                           

     

b)

Whois  

c)

Nmap

d)

Burp Suite

39.

What does IP address range footprinting reveal?

a)

Website content

     

b)

Network structure

c)

User credentials

d)

Software versions

40.

Which tool is used to view the historical data of a website?

a)

Nmap

     

b)

Wayback Machine

c)

Wireshark

d)

John the Ripper

41.

What is banner grabbing in fingerprinting?

a)

Capturing network packets

    

b)

Retrieving service version information

c)

Scanning web applications

d)

Enumerating DNS records

42.

Which protocol is commonly used for banner grabbing?

a)

HTTP                                                                       

     

b)

FTP

c)

DNS

d)

ICMP

43.

What is application fingerprinting?

a)

Identifying user accounts

     

b)

Determining software versions

c)

Scanning network ports

d)

Cracking passwords    

44.

Which tool is used for web application scanning?

a)

Nmap                     

     

b)

Burp Suite

c)

Whois       

d)

DNSenum

45.

What is DNS fingerprinting?

a)

Identifying DNS server versions

     

b)

Scanning web servers

c)

Capturing network traffic

d)

Exploiting vulnerabilities

46.

What is DNS enumeration?

a)

Scanning network ports

     

b)

Listing DNS records

c)

Cracking passwords

d)

Hiding tracks

47.

Which tool is used for DNS enumeration?

a)

Nmap                            

     

b)

DNSenum

c)

Metasploit

d)

Wireshark

48.

What is a passive reconnaissance technique?

a)

Port scanning                 

     

b)

Querying Whois database

c)

Banner grabbing

d)

Vulnerability scanning

49.

Which command-line tool resolves domain names to IP addresses?

a)

nslookup                                                                

b)

ping

c)

tracert

d)

netcat

50.

What information can be obtained from the Wayback Machine?

a)

Current website content

               

b)

Historical website snapshots

c)

Network traffic data

d)

User login details

51.

Which type of reconnaissance avoids detection by not interacting with the target?

a)

Active Reconnaissance                                           

     

b)

Passive Reconnaissance

c)

DNS Enumeration

d)

Web Scanning

52.

What is the purpose of footprinting in ethical hacking?

a)

Exploit vulnerabilities

     

b)

Gather target information

c)

Install backdoors

d)

Encrypt data

53.

Which tool can perform both port scanning and banner grabbing?

a)

Nmap

b)
Wireshark
c)
Netcat
d)
Telnet
54.

What does a hosting company provide for a website?

a)

Domain name registration

     

b)

Server infrastructure

c)

Network security

d)

User authentication

55.

Which record type is commonly enumerated in DNS footprinting?

a)

MX

     

b)

TXT   

c)

CNAME

d)

All of the above

56.

What is a limitation of passive reconnaissance?

a)

High detection risk

                       

b)

Limited information depth

c)

Requires system access

d)

Always illegal

57.

Which tool is used for analyzing HTTP responses in web application scanning?

a)

Burp Suite                                                     

     

b)

Nmap       

c)

DNSenum

d)

Wireshark

58.

What does the NS record in DNS enumeration indicate?

a)

Mail server

     

b)

Name server

c)

Canonical name

d)

IP address

59.

Which fingerprinting technique identifies web server software?

a)

Banner Grabbing

     

b)

DNS Enumeration

c)

Port Scanning

d)

Password Cracking

60.

What is a key benefit of footprinting?

a)

Immediate system access

    

b)

Detailed target profile

c)

Guaranteed exploits

d)

Hiding tracks

61.

What distinguishes ethical hacking from non-ethical hacking?

a)

Intent and permission

     

b)

Tools used      

c)

Speed of attack

d)

Target selection

62.

Which two phases of hacking are critical for identifying vulnerabilities?

a)

Reconnaissance and Exploitation

     

b)

Scanning and Enumeration        

c)

Exploitation and Covering Tracks

d)

Maintaining Access and Reporting

63.

Which components of the CIA triad are most affected by unauthorized access?

a)

Integrity and Availability                  

     

b)

Confidentiality and Integrity

c)

Confidentiality and Availability

d)

Integrity and Authentication      

64.

Under the Indian IT Act 2000, which sections address hacking and data breaches?

a)

Sections 43 and 66

     

b)

Sections 67 and 69

c)

Sections 43A and 70

d)

Sections 66 and 67      

65.

What are two key advantages of ethical hacking?

a)

Data theft and system disruption

   

b)

Security improvement and vulnerability identification

c)

Financial gain and unauthorized access

d)

Malware creation and network crashes  

66.

Which two tools are commonly used for network and vulnerability scanning?

a)

Metasploit and John the Ripper

     

b)

Nmap and Nessus

c)

Wireshark and Burp Suite

d)

Aircrack-ng and Photoshop

67.

What are two key skills required for ethical hacking?

a)

Programming and networking

     

b)

Graphic design and database management

c)

Web development and social media marketing

d)

Hardware repair and system administration

68.

Which two types of hackers may operate without malicious intent?

a)

Black Hat and Grey Hat

     

b)

White Hat and Grey Hat

    

c)

Script Kiddie and Black Hat

d)

White Hat and Script Kiddie

69.

What are two disadvantages of ethical hacking?

a)

Time-consuming and costly

     

b)

Improves security and prevents breaches

c)

Illegal and unethical       

d)

Enhances skills and reduces risks

70.

Which two phases of hacking involve active interaction with the target system?

a)

Reconnaissance and Scanning

     

b)

Scanning and Exploitation

c)

Exploitation and Maintaining Access

d)

      Covering Tracks and Reporting

71.

Which two elements of the Indian IT Act 2000 were strengthened in the 2008 amendment?

a)

Hacking penalties and data protection

    

b)

Cybercrime definitions and physical security

c)

Software licensing and hardware regulation

d)

Network monitoring and surveillance

72.

What are two common ethical hacking terminologies?

a)

Phishing and Brute Force

     

b)

Malware and Firewall

c)

Router and Switch

d)

Encryption and Decryption

73.

Which two tools are used for web application testing in ethical hacking?

a)

Burp Suite and OWASP ZAP

    

b)

Nmap and Wireshark

c)

Nessus and John the Ripper

d)

Metasploit and Aircrack-ng

74.

What are two purposes of ethical hacking?

a)

Identify vulnerabilities and improve security

   

b)

Steal data and disrupt systems

c)

Create malware and exploit networks

d)

Gain unauthorized access and hide tracks

75.

Which two aspects of the CIA triad are compromised by a DDoS attack?

a)

Integrity and Availability

     

b)

Confidentiality and Integrity

c)

Confidentiality and Availability

d)

Authentication and Non-repudiation

76.

What are two key differences between active and passive reconnaissance?

a)

Direct interaction vs. no interaction, high vs. low detection risk

     

b)

Uses same tools, same detection risk

c)

Requires exploits vs. no exploits

d)

Illegal vs. legal

77.

Which two tools are commonly used for footprinting domain name and IP information?

a)

Nmap and Burp Suite                                                                                                             

 

b)

Whois and nslookup

c)

Metasploit and Wireshark

d)

DNSenum and John the Ripper

78.

What are two types of information gathered during footprinting?

a)

Domain registration and IP ranges                          

     

b)

User passwords and system exploits

c)

Network traffic and malware signatures

d)

Website content and encryption keys

79.

Which two techniques are used in fingerprinting to identify system details?

a)

Banner Grabbing and Application Fingerprinting                 

     

b)

Port Scanning and Password Cracking

c)

DNS Enumeration and Malware Injection

d)

Web Scanning and Brute Forcing

80.

What are two purposes of DNS enumeration?          

a)

Identify name servers and mail servers

    

b)

Crack passwords and gain access

c)

Scan ports and exploit vulnerabilities

d)

Hide tracks and encrypt data     

81.

Which two tools are used for web application scanning and fingerprinting?

a)

Burp Suite and OWASP ZAP                 

     

b)

Nmap and Whois

c)

DNSenum and Metasploit

d)

Wireshark and John the Ripper

82.

What are two benefits of passive reconnaissance?

a)

Low detection risk and legal

     

b)

Immediate access and exploits

c)

High accuracy and system control

d)

Requires no tools and fast

83.

Which two types of DNS records are commonly enumerated?

a)

MX and A

     

b)

TXT and PTR       

c)

CNAME and NS

d)

All of the above

84.

What are two limitations of active reconnaissance?

a)

High detection risk and resource-intensive

     

b)

Limited information and illegal

c)

Requires no tools and slow

d)

Guarantees exploits and access

85.

Which two sources provide historical website data in footprinting?

a)

Wayback Machine and Whois

     

b)

Nmap and Burp Suite

c)

DNSenum and Wireshark

d)

Metasploit and nslookup

86.

What are two key pieces of information obtained from a Whois lookup?

a)

Domain owner and registrar

     

b)

IP address and network traffic

c)

Website content and user data

d)

Exploits and vulnerabilities     

87.

Which two fingerprinting techniques target web applications?

a)

Web Application Scanning and Application Fingerprinting

    

b)

Banner Grabbing and DNS Enumeration

c)

Port Scanning and Brute Forcing

d)

DNS Fingerprinting and Malware Analysis

88.

What are two tools used for banner grabbing?

a)

Nmap and Netcat

     

b)

Whois and DNSenum

c)

Burp Suite and Wireshark

d)

Metasploit and John the Ripper

89.

Which two activities are part of active reconnaissance?

a)

Port scanning and banner grabbing

     

b)

Querying Whois and using Wayback Machine

c)

DNS enumeration and web scanning            

d)

Password cracking and exploit testing

90.

What are two outcomes of effective footprinting?

a)

Detailed network map and vulnerability identification

    

b)

System access and data theft

c)

Malware installation and track covering

d)

Encryption and authentication